Job Responsibilities:
- Support sales efforts by attending security sales meetings when necessary, providing effort estimations, and outlining project timelines for security testing.
- Develop security acceptance test plans.
- Offer expert technical support during security testing activities.
- Prepare for security tests by setting up testing environments, configuring, and installing security testing tools.
- Conduct manual or automated security testing using commercial security testing tools.
- Perform Greybox Testing (Authenticated) and/or Blackbox Testing (Unauthenticated) Penetration Tests.
- Conduct Whitebox Testing and Secure Code Review.
- Perform Network and Infrastructure Vulnerability Assessment and Penetration Testing.
- Perform Web, Mobile, and Desktop Application Vulnerability Assessment and Penetration Testing.
- Identify and pinpoint vulnerabilities in the assessed target systems/applications.
- Document and report identified vulnerabilities in the system.
- Provide professional recommendations and advice to mitigate and resolve vulnerabilities.
- Present security testing results to relevant stakeholders.
- Provide weekly status reports on the progress of security testing activities.
Key Requirements:
- Possession of one of the following certifications:CREST Registered Penetration Tester (CREST CRT)
Offensive Security Certified Professional (OSCP)
- Knowledge of conducting security testing adhering to guidelines and standards such as:Open Web Application Security Project (OWASP Top 10 Frameworks)
Common Vulnerability Scoring System (CVSS)
Common Vulnerabilities and Exposures (CVE)
Common Weakness Enumeration (CWE) / SANS Top 25 Software Errors
- High proficiency in manual and automated techniques for penetration testing across various systems and applications, including but not limited to network equipment, servers, web applications, APIs, wireless systems, mobile applications, and databases. Techniques include vulnerability assessments for injection, privilege escalation, fuzzing, buffer overflows, etc.
- Familiarity with tools such as Proxies, Port Scanners, Vulnerability Scanners, and Exploit Frameworks (e.g., Burp, Nessus, Nmap, Metasploit).
Interested candidates, who wish to apply for the above position, please send in your resume to [email protected].
We regret to inform that only shortlisted candidates will be contacted.
PERSOLKELLY Singapore Pte Ltd
EA License No. 01C4394
EA Reg No: R1875348 (Tewari Priyanka)
**********************************
By sending us your personal data and curriculum vitae (CV), you are deemed to consent to PERSOLKELLY Singapore Pte Ltd and its affiliates to collect, use and disclose your personal data for the purposes set out in the Privacy Policy available